Particle.news
Download on the App Store

Phishing Emails Impersonating Interpol Deliver Custom Ransomware to Small Businesses

Researchers say the active campaign relies on passworded Proton Drive files to trick recipients into opening a multi‑layer archive that hides the malware.

Overview

  • Bitdefender Antispam Lab publicly documented the campaign in a July 1 report after observing emails that pose as Interpol investigators and point victims to a Proton Drive link.
  • The messages include a password and a file named archive.rar so recipients can open a password‑protected multi‑layer archive that ultimately runs an executable disguised as a video.
  • The deployed malware encrypts files, drops a ransom note that forbids scanning or moving files, and instructs victims to negotiate through the Tox encrypted messenger without listing a fixed ransom.
  • Researchers describe the code as custom and relatively simple, and they say the operation appears smaller and targeted, with victims in Europe, Asia, the Middle East and the United States across multiple sectors.
  • Security advice for small businesses includes verifying unsolicited investigative notices out of band, inspecting file extensions before opening, avoiding running unknown executables, and submitting suspicious links or files to scanners such as VirusTotal.